VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18467CVEs
CVE-2024-44984
bnxt_en: Fix double DMA unmapping for XDP_REDIRECT
Published 2024-09-04 · Modified
10.0EPSS 0.007
CVE-2025-30412
Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.
Published 2026-02-20 · Analyzed
10.0EPSS 0.007
CVE-2025-57870
BUG-000179884 - There is a security vulnerability in ArcGIS Server Feature Services.
Published 2025-10-22 · Analyzed
10.0EPSS 0.005
CVE-2026-63795
9p: avoid putting oldfid in p9_client_walk() error path
Published 2026-07-19 · Analyzed
10.0EPSS 0.005
CVE-2024-56719
net: stmmac: fix TSO DMA API usage causing oops
Published 2024-12-29 · Modified
10.0EPSS 0.005
CVE-2025-30416
Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.
Published 2026-02-20 · Analyzed
10.0EPSS 0.005
CVE-2025-22021
netfilter: socket: Lookup orig tuple for IPv6 SNAT
Published 2025-04-16 · Modified
10.0EPSS 0.005
CVE-2025-21663
net: stmmac: dwmac-tegra: Read iommu stream id from device tree
Published 2025-01-21 · Modified
10.0EPSS 0.004
CVE-2025-38429
bus: mhi: ep: Update read pointer only after buffer is written
Published 2025-07-25 · Modified
10.0EPSS 0.004
CVE-2026-83660
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-09-22 · Analyzed
10.0EPSS 0.003
CVE-2026-13782
Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-30 · Modified
10.0EPSS 0.003
CVE-2026-64879
Command Injection
Published 2026-07-21 · Analyzed
9.9EPSS 0.023
CVE-2022-37425
The FILES directive inside a VM template allows execution of uploaded files when the template is instantiated, resulting in a Remote Code Execution (RCE) attack.
Published 2022-10-28 · Modified
9.9EPSS 0.016
CVE-2023-35893
IBM Security Guardium command execution
Published 2023-08-16 · Modified
9.9EPSS 0.014
CVE-2023-27874
IBM Aspera Faspex XML external entity injection
Published 2023-03-21 · Modified
9.9EPSS 0.013
CVE-2024-25693
Portal for ArcGIS has a directory traversal vulnerability.
Published 2024-04-04 · Analyzed
9.9EPSS 0.013
CVE-2021-26334
AMD Chipset Driver Information Disclosure Vulnerability
Published 2021-12-01 · Modified
9.9EPSS 0.012
CVE-2022-28181
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. The scope of the impact may extend to other components.
Published 2022-05-17 · Modified
9.9EPSS 0.011
CVE-2026-8476
Disk Cache Deserialization Remote Code Execution Vulnerability
Published 2026-07-17 · Analyzed
9.9EPSS 0.010
CVE-2026-82010
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-09-22 · Analyzed
9.9EPSS 0.010
CVE-2026-48326
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-08-03 · Analyzed
9.9EPSS 0.010
CVE-2026-8481
Remote Code Execution via Code Validation Endpoint
Published 2026-07-17 · Analyzed
9.9EPSS 0.009
CVE-2026-65083
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.
Published 2026-08-25 · Analyzed
9.9EPSS 0.009
CVE-2026-9135
Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation
Published 2026-07-17 · Analyzed
9.9EPSS 0.008
CVE-2026-82013
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-09-22 · Analyzed
9.9EPSS 0.008
CVE-2026-65093
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
Published 2026-08-25 · Analyzed
9.9EPSS 0.008
CVE-2026-64878
Command Injection
Published 2026-07-21 · Analyzed
9.9EPSS 0.008
CVE-2026-2749
Path traversal in Centreon Open Tickets
Published 2026-02-27 · Analyzed
9.9EPSS 0.006
CVE-2026-8859
Path Traversal in APIRequest Component via Content-Disposition Header
Published 2026-07-17 · Analyzed
9.9EPSS 0.006
CVE-2026-82008
Adobe Campaign Classic (ACC) | Improper Input Validation (CWE-20)
Published 2026-09-22 · Analyzed
9.9EPSS 0.005
CVE-2026-8635
Arbitrary Code Execution in Python Interpreter Component
Published 2026-07-17 · Analyzed
9.9EPSS 0.005
CVE-2026-89276
Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-09-22 · Analyzed
9.9EPSS 0.005
CVE-2026-82443
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-09-22 · Analyzed
9.9EPSS 0.004
CVE-2022-47986
IBM Aspera Faspex code execution
Published 2023-02-17 · Analyzed
9.8KEV1 PoCEPSS 1.000
CVE-2020-13160
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.
Published 2020-06-09 · Modified
9.81 PoCEPSS 0.806
CVE-2024-1222
Incorrect authorization controls in PaperCut NG/MF APIs
Published 2024-03-14 · Analyzed
9.8EPSS 0.640
CVE-2023-28503
Authentication bypass in UniRPC's udadmin service
Published 2023-03-29 · Modified
9.8EPSS 0.621
CVE-2023-28502
Stack buffer overflow in UniRPC's udadmin_server service
Published 2023-03-29 · Modified
9.8EPSS 0.611
CVE-2021-43267
An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.
Published 2021-11-02 · Modified
9.8EPSS 0.579
CVE-2022-22972
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
Published 2022-05-20 · Modified
9.8EPSS 0.563
← Prev14 / 462Next →